MediaTek DA Uninitialized Heap Data Vulnerability Leading to Information Disclosure

Vulnerability

A vulnerability exists in the MediaTek DA component, where uninitialized heap data can be read. This issue could allow local information disclosure if an attacker has physical access to the device, without requiring any additional execution privileges. Exploitation of this vulnerability does require user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information stored in memory.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch are available through the MediaTek product security bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.3
remediation
6.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.